Secunia Logo
 
FDclone Insecure Temporary Files
Secunia Advisory: SA9330
Release Date: 2003-07-23
Popularity: 7,003 views

Critical:
Less critical
Impact: Manipulation of data
Where: Local system
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.0
Debian GNU/Linux unstable alias sid

Software:FDclone 2.x

Subscribe: Instant alerts on relevant vulnerabilities


Description:
A vulnerability has been identified in FDclone allowing malicious users to manipulate temporary files.

The problem is that FDclone doesn't check if the temporary directory already exists and starts using it. This allows malicious users to manipulate the temporary files and possibly escalate privileges.

Solution:
Updated packages:

Debian GNU/Linux 3.0 alias woody

Source archives:

http://security.debian.org/pool/updates/main/f/fdclone/fdclone_2.00a-1woody3.dsc
Size/MD5 checksum: 579 f350493d71e75dad2f3191c8d12e1c91
http://security.debian.org/pool/updat...fdclone/fdclone_2.00a-1woody3.diff.gz
Size/MD5 checksum: 14585 97dd0d685268c7c4a326812d5ba1da89
http://security.debian.org/pool/updates/main/f/fdclone/fdclone_2.00a.orig.tar.gz
Size/MD5 checksum: 539774 d5b6245117c9292ac8b3ae6107e72069

Alpha architecture:

http://security.debian.org/pool/updat...clone/fdclone_2.00a-1woody3_alpha.deb
Size/MD5 checksum: 400620 f1ab7c3886a23779e0f78e2d7da794d0

ARM architecture:

http://security.debian.org/pool/updat...fdclone/fdclone_2.00a-1woody3_arm.deb
Size/MD5 checksum: 358782 522aed8f7baf8f22b6c4dcb60e25ff85

Intel IA-32 architecture:

http://security.debian.org/pool/updat...dclone/fdclone_2.00a-1woody3_i386.deb
Size/MD5 checksum: 346522 825a4386e090da06833581a4ae707f17

HP Precision architecture:

http://security.debian.org/pool/updat...dclone/fdclone_2.00a-1woody3_hppa.deb
Size/MD5 checksum: 376718 0f2bc10c4460e7134e6c0fb621722c22

Motorola 680x0 architecture:

http://security.debian.org/pool/updat...dclone/fdclone_2.00a-1woody3_m68k.deb
Size/MD5 checksum: 330932 c4741850e9dcf1d268b78bed29561f1f

PowerPC architecture:

http://security.debian.org/pool/updat...one/fdclone_2.00a-1woody3_powerpc.deb
Size/MD5 checksum: 361912 a60bc8ff2744766577177d9fafcebef4

IBM S/390 architecture:

http://security.debian.org/pool/updat...dclone/fdclone_2.00a-1woody3_s390.deb
Size/MD5 checksum: 352768 fbb33dbe7d8a1d118187e1c8cad69ed0

Sun Sparc architecture:

http://security.debian.org/pool/updat...clone/fdclone_2.00a-1woody3_sparc.deb
Size/MD5 checksum: 360160 56b9373f4805f113750db0fdd6329dba


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 65 views
2. Adobe Acrobat/Reader Multiple Vulnerabilities // 35 views
3. Linksys WRT160N Cross-Site Scripting Vulnerability // 31 views
4. ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability // 29 views
5. Debian update for flamethrower // 28 views
6. IBM Rational ClearQuest Multiple Vulnerabilities // 27 views
7. DAHDI "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerability // 26 views
8. Rumpus Multiple Vulnerabilities // 25 views
9. IBM Rational ClearCase Cross-Site Scripting Vulnerability // 25 views
10. Zeroboard Multiple Vulnerabilities // 24 views